Illinois Governor Signs Landmark AI Act With First-in-Nation Mandatory Third-Party Audit for Frontier Models
Illinois has enacted the Artificial Intelligence Safety Measures Act, becoming the first U.S. state to mandate annual independent third-party audits for developers of massive frontier AI models. The legislation joins similar frameworks in California and New York to solidify a de facto national standard for AI safety and transparency.
By Logan Price
- State Regulators
- Argue that states must lead on AI safety to protect the public amid federal inaction.
- Legal & Compliance Experts
- Focus on the operational impact of the law and the emergence of a de facto national standard.
- Consumer Advocates
- Praise the transparency measures but criticize the inability of individuals to sue for AI-driven harms.
Perspectives this story doesn't cover
- Open-Source AI Developers who might fear future regulatory creep.
- Independent AI Auditors who will be tasked with executing these complex technical evaluations.
The short answer
- Illinois is the first U.S. state to mandate independent third-party safety audits for large AI developers.
- The law applies only to frontier models trained with massive computing power by companies earning over $500 million annually.
- Developers must report critical safety incidents to state emergency agencies within 24 to 72 hours.
- The legislation relies on the state Attorney General for enforcement, with fines reaching up to $3 million for repeat offenses.
- Combined with similar laws in California and New York, the act helps establish a de facto national standard for AI safety.
Illinois Governor JB Pritzker has signed the Artificial Intelligence Safety Measures Act (SB 315) into law, establishing one of the most stringent regulatory frameworks for advanced AI in the United States. The legislation makes Illinois the first state to require mandatory, independent third-party audits for developers of massive "frontier" AI models. [1][3][1][3]
The new law targets the largest and most resource-intensive artificial intelligence systems—specifically those trained using more than 10²⁶ floating-point operations by companies generating over $500 million in annual revenue. [6][7] By setting these high thresholds, the legislation focuses squarely on industry giants like OpenAI, Google, Anthropic, and Meta, rather than stifling smaller startups or open-source researchers. [4][6][4][6]
The centerpiece of the legislation is its unprecedented audit mandate. Beginning in 2028, large frontier developers must hire independent third-party evaluators to annually assess their compliance with safety protocols and internal risk controls. [6][8] Crucially, the law stipulates strict independence criteria, ensuring that auditors have no financial conflicts of interest with the tech companies they are evaluating. [8][6][7]
Beyond audits, the law requires developers to publish comprehensive safety frameworks detailing how they identify and mitigate "catastrophic risks"—such as the potential for an AI model to assist in creating biological weapons or executing large-scale cyberattacks. [1][7] Companies must also report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours, or just 24 hours if the risk is deemed imminent. [5][6][1][5][6]
Enforcement of the new regulations falls exclusively to the Illinois Attorney General, who can levy civil penalties of up to $1 million for a first violation and $3 million for subsequent offenses. [3][8] The legislation does not include a private right of action, meaning individual citizens cannot sue AI companies directly under this specific law for algorithmic harms, a compromise that helped secure broad bipartisan support. [4][5][3][4][5][7]
During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock. He emphasized that the state is choosing a path of "innovation with security," ensuring that the costs and detriments of unchecked technological growth are not pushed onto ordinary citizens. [1][3] Pritzker openly criticized Congress for remaining captive to special interests and failing to pass a cohesive national framework. [1][2][1][2][3]
During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock.
Illinois now joins California and New York, which passed similar frontier AI transparency laws in late 2025. [1][2] Legal experts note that because these three states collectively account for roughly 40% of the U.S. AI market, their combined regulations effectively create a de facto national standard. [1][6] It is logistically unfeasible for major tech companies to build separate AI models for different states, meaning the Illinois audit requirement will likely become standard industry practice nationwide. [6][8][1][2][6][7]
The tech industry's reaction has been surprisingly cooperative. Major players like OpenAI have publicly endorsed the Illinois framework, describing it as one of the strongest safety laws in the country. [6] This support reflects a growing consensus among leading labs that clear, predictable state regulations are preferable to a chaotic patchwork of conflicting local ordinances or the looming threat of more draconian federal interventions. [6][7][6]
The transparency and reporting provisions of the Artificial Intelligence Safety Measures Act will officially take effect on January 1, 2027, giving developers a brief runway to align their internal compliance programs. [6][8] The more rigorous third-party audit requirements will follow a year later in 2028, marking a critical transition from an era of self-reported AI safety to one of verified, independent oversight. [7][8][6][7]
Why it matters
By mandating independent safety audits for the world's most powerful AI systems, Illinois is closing a major loophole in tech oversight. Because the law applies to any major developer doing business in the state, it effectively forces national compliance, giving the public unprecedented visibility into the risks of frontier models.
Jargon, explained
- Frontier Model
- A highly capable foundation AI model trained using massive amounts of computing power, typically exceeding 10²⁶ floating-point operations.
- Third-Party Audit
- An independent evaluation conducted by an external organization to verify that a company is complying with safety and regulatory standards.
- Private Right of Action
- A legal provision that allows ordinary citizens to file lawsuits directly against a company for violating a specific law.
- Catastrophic Risk
- The potential for an AI system to cause large-scale harm, such as assisting in the creation of biological weapons or facilitating severe cyberattacks.
Sources
[1]Capitol News IllinoisState RegulatorsPritzker signs landmark AI regulation bill that aims to mitigate risks
Read on Capitol News Illinois →
[2]The Washington PostState RegulatorsGov. JB Pritzker has signed a new artificial intelligence law in Illinois
Read on The Washington Post →
[3]JURISTState RegulatorsIllinois Governor JB Pritzker signs landmark artificial intelligence bill
Read on JURIST →
[4]The Legal ExaminerConsumer AdvocatesWhat Does the Illinois Artificial Intelligence Safety Measures Act Do?
Read on The Legal Examiner →
[5]Transparency CoalitionConsumer AdvocatesIllinois Gov. Pritzker signs nation's 'most protective' AI Safety Measures Act into law
Read on Transparency Coalition →
[6]SkaddenLegal & Compliance ExpertsIllinois Imposes Transparency and Safety Obligations on Frontier AI Systems
Read on Skadden →
[7]Latham & WatkinsLegal & Compliance ExpertsIllinois' SB 315 is the first law in the US to mandate third-party audits for large AI developers
Read on Latham & Watkins →
Comments
More in Artificial Intelligence
See all →Neural Networks
How Batch Normalization Accelerates Deep Network Convergence
7 sources
Algorithm Mechanics
How Monte Carlo Tree Search Balances Exploration and Exploitation Using the UCB1 Formula
3 sources
Machine Learning
How the Kernel Trick Implicitly Maps Data to a Higher-Dimensional Feature Space to Achieve Linear Separability
7 sources
Model Architecture
How Layer Normalization Stabilizes Transformer Training by Standardizing Input Across the Feature Dimension
7 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.




